{"id":"circulars/cssf-20-750","title":"Circular CSSF 20/750","type":"circular","date":"2020-08-25","kind":"circular","html":"<p>Circular CSSF 20/750 is a CSSF circular, published 25 August 2020. Subject: Requirements regarding information and communication technology (ICT) and security risk management.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F1993-04-05-n1\" class=\"wikiLink\" data-target=\"laws/1993-04-05-n1\">Law of 5 April 1993 on the financial sector</a>, <a href=\"/lhoft?page=laws%2F2000-12-15-n1\" class=\"wikiLink\" data-target=\"laws/2000-12-15-n1\">Law of 15 December 2000 on postal services and postal financial services</a>.</p>\n<p>Relevant for: AISPs, Credit institutions, Data Reporting Service Providers (DRSPs), E-money institutions, Investment firms, Payment institutions, Payment institutions/electronic money institutions/AISPs, Specialised PFS, Support PFS.</p>\n<p>Keywords: Cloud, Cybersecurity, eDesk, Information and communications technology (ICT), Information security, Operational risk, Payment Service Provider (PSP), Payment services, Postal financial services, Risk management.</p>\n<p>Amended by <a href=\"/lhoft?page=circulars%2Fcssf-22-828\" class=\"wikiLink\" data-target=\"circulars/cssf-22-828\">Circular CSSF 22/828</a>, <a href=\"/lhoft?page=circulars%2Fcssf-25-881\" class=\"wikiLink\" data-target=\"circulars/cssf-25-881\">Circular CSSF 25/881</a>, <a href=\"/lhoft?page=circulars%2Fcssf-26-915\" class=\"wikiLink\" data-target=\"circulars/cssf-26-915\">Circular CSSF 26/915</a>. Repeals <a href=\"/lhoft?page=circulars%2Fcssf-19-713\" class=\"wikiLink\" data-target=\"circulars/cssf-19-713\">Circular CSSF 19/713</a>.</p>\n<h2>Text</h2>\n<p>on requirements regarding information and communication technology (ICT) and security risk management</p>\n<p>on requirements regarding information and technology (ICT) and security risk management</p>\n<p>communication</p>\n<p>To support PFS and specialised PFS within the meaning of the Law of 5 April 1993 on the financial sector (LFS), and POST Luxembourg governed by the Law of 15 December 2000 on postal financial services 1.</p>\n<p>Luxembourg, 25 August 2020</p>\n<p>Ladies and Gentlemen,</p>\n<p>This circular reflects the expectations of the CSSF as regards the risk management measures and control and security arrangements as referred to in Articles 17(1a) and 36(1) of the Law of 5 April 1993 on the financial sector (“LFS”) and in Article 105-1 (1) of the Law of 10 November 2009 on payment services (“LPS”). This circular is divided in four Chapters: •</p>\n<p>Chapter 1 indicates the scope of this circular</p>\n<p>Chapter 2 provides definitions and clarifications with regards to the terms used in this circular</p>\n<p>Chapter 3 lists the requirements regarding ICT and security risk management</p>\n<p>Chapter 4 indicates the entry into force of this circular</p>\n<p>1 For the sake of clarity, the wording “postal financial services” has the meaning provided for in Article 1 of the Law of 15 December 2000 as amended.</p>\n<p>CIRCULAR CSSF 20/750 as amended by Circulars CSSF 22/828, CSSF 25/881 and CSSF 26/915</p>\n<p>TABLE OF CONTENTS Chapter 1.</p>\n<p>Entities in Scope ........................................................................................... 4</p>\n<p>Chapter 2.</p>\n<p>Definitions.................................................................................................... 4</p>\n<p>Chapter 3.</p>\n<p>Guidelines on ICT and security risk management .............................................. 5</p>\n<p>3.1.</p>\n<p>Proportionality .......................................................................................... 5</p>\n<p>3.2.</p>\n<p>Governance and strategy ........................................................................... 6</p>\n<p>3.3.</p>\n<p>ICT and security risk management framework .............................................. 7</p>\n<p>3.4.</p>\n<p>Information security.................................................................................. 9</p>\n<p>3.5.</p>\n<p>ICT operations management .................................................................... 13</p>\n<p>3.6.</p>\n<p>ICT project and change management ........................................................ 15</p>\n<p>3.7.</p>\n<p>Business continuity management .............................................................. 17</p>\n<p>Chapter 4.</p>\n<p>Date of application ...................................................................................... 19</p>\n<p>CIRCULAR CSSF 20/750 as amended by Circulars CSSF 22/828, CSSF 25/881 and CSSF 26/915</p>\n<p>Chapter 1. Entities in Scope This circular is applicable in full to all the following entities: a) All support PFS within the meaning of the Law of 5 April 1993 on the financial sector (LFS) b) All specialised PSF within the meaning of the Law of 5 April 1993 on the financial sector (LFS) c)</p>\n<p>POST Luxembourg governed by the Law of 15 December 2000 on postal financial services 2 and as Payment Service Provider as referred to in Article 1(37)(iii) of the LPS</p>\n<p>Chapter 2. Definitions Financial Institution</p>\n<p>Throughout this document this term refers to the supervised entities in scope of this circular as defined in Chapter 1.</p>\n<p>Payment Service Provider (PSP)</p>\n<p>Throughout this document this term refers to POST Luxembourg.</p>\n<p>ICT and security risk</p>\n<p>Risk of loss due to breach of confidentiality, failure of integrity of systems and data, inappropriateness or unavailability of systems and data or inability to change information technology (IT) within a reasonable time and with reasonable costs when the environment or business requirements change (i.e. agility).</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-20-750/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf20_750eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}